Additions by year
2021–2022 include the catalogue's launch backlog, not fresh exploitation of those years
| Year | Added | Share of catalogue | Ransomware-linked |
|---|---|---|---|
| 2021 | 311 | 18.3% | 27% |
| 2022 | 555 | 32.6% | 24% |
| 2023 | 187 | 11.0% | 23% |
| 2024 | 186 | 10.9% | 24% |
| 2025 | 245 | 14.4% | 13% |
| 2026 | 219 | 12.9% | 11% |
How old a CVE is when exploitation is confirmed
Catalogue year minus CVE identifier year — an assignment-year proxy, see the note below
| Age at entry | Records | Share |
|---|---|---|
| Same year | 739 | 43.4% |
| 1 year | 272 | 16.0% |
| 2–4 years | 323 | 19.0% |
| 5–9 years | 273 | 16.0% |
| 10+ years | 96 | 5.6% |
Old vulnerabilities, fresh exploitation
CVEs at least a decade old when CISA confirmed attacks, added since 2025
| CVE | Vendor / product | Age at entry | Added |
|---|---|---|---|
| CVE-2007-0671 | Microsoft / Office | 18 years | 2025-08-12 |
| CVE-2008-0015 | Microsoft / Windows | 18 years | 2026-02-17 |
| CVE-2008-4128 | Cisco / IOS | 18 years | 2026-07-13 |
| CVE-2008-4250 | Microsoft / Windows | 18 years | 2026-05-20 |
| CVE-2009-0238 | Microsoft / Office | 17 years | 2026-04-14 |
| CVE-2009-0556 | Microsoft / Office | 17 years | 2026-01-07 |
| CVE-2009-1537 | Microsoft / DirectX | 17 years | 2026-05-20 |
| CVE-2009-3459 | Adobe / Acrobat and Reader | 17 years | 2026-05-20 |
Vendors
All-time and the last 12 months (290 additions)
| Vendor | All time | Share | Last 12 months |
|---|---|---|---|
| Microsoft | 388 | 22.8% | 48 |
| Cisco | 97 | 5.7% | 19 |
| Apple | 94 | 5.5% | 10 |
| Adobe | 81 | 4.8% | 7 |
| 74 | 4.3% | 10 | |
| Oracle | 46 | 2.7% | 7 |
| Apache | 40 | 2.3% | 2 |
| Ivanti | 35 | 2.1% | 5 |
| Fortinet | 30 | 1.8% | 10 |
| Linux | 28 | 1.6% | 6 |
| D-Link | 26 | 1.5% | 2 |
| VMware | 26 | 1.5% | — |
| Citrix | 24 | 1.4% | 3 |
| Synacor | 19 | 1.1% | 6 |
| SonicWall | 19 | 1.1% | 5 |
Remediation windows
Days between a record entering KEV and its federal deadline
| Window | Records | Share |
|---|---|---|
| 7 days or less | 135 | 7.9% |
| 8–21 days | 1304 | 76.6% |
| 22–90 days | 7 | 0.4% |
| Over 90 days | 257 | 15.1% |
Method, honestly
Everything above is computed from the CISA KEV catalogue as of 2026-09-09. "Age at entry" uses the year embedded in the CVE identifier, which is the year the identifier was assigned — usually but not always the disclosure year, so treat single-year precision with care. Ransomware share reflects CISA's "known ransomware campaign use" flag, which is conservative: absence of the flag is not evidence of absence. Reproduce or extend any of this from the public JSON; if you publish something based on it, a link back is appreciated.